40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-20464
Software Genérico General
7.5
HIGH
EPSS
0.4%
2019 1 PoC

An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over UDP. However, the device offers many more services that also enable streaming. Although the service used by the mobile application requires a password, the other streaming services do not. By initiating communication on the RTSP port, an attacker can obtain access to the video feed without authenticating.

CVE-2022-40303
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 5 PoCs

An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.

CVE-2025-61104
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

CVE-2020-12524
BTP Touch Panel General
7.5
HIGH
EPSS
0.3%
2020 CWE-400 1 PoC

Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).

CVE-2019-15961
ClamAV General
7.5
HIGH
EPSS
2.2%
2019 CWE-20 2 PoCs

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denia

CVE-2025-3194
bigint-buffer General
7.5
HIGH
EPSS
0.4%
2025 CWE-120 1 PoC

Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.

CVE-2019-9099
Software Genérico General
7.5
HIGH
EPSS
9.1%
2019 1 PoC

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2).

CVE-2019-5188
E2fsprogs General
7.5
HIGH
EPSS
0.1%
2019 CWE-787 1 PoC

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVE-2019-5091
LEADTOOLS libltdic.so General
7.5
HIGH
EPSS
0.4%
2019 CWE-835 1 PoC

An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an infinite loop, resulting in a denial of service. An attacker can send a packet to trigger this vulnerability.

CVE-2019-9564
Cam Pan v2 General
7.5
HIGH
EPSS
0.4%
2019 1 PoC

A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to 4.36.8.32.

CVE-2017-3143
BIND 9 General
7.5
HIGH
EPSS
26.9%
2017 1 PoC

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVE-2021-41719
Software Genérico General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.

CVE-2022-42277
NVIDIA DGX servers General
7.5
HIGH
EPSS
0.0%
2022 CWE-288 1 PoC

NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

CVE-2019-25073
github.com/goadesign/goa General
7.5
HIGH
EPSS
0.6%
2019 1 PoC

Improper path sanitization in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory.

CVE-2019-10936
Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller General
7.5
HIGH
EPSS
2.0%
2019 CWE-400 1 PoC

Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.

CVE-2019-3628
McAfee Enterprise Security Manager (ESM) General
7.5
HIGH
EPSS
0.8%
2019 1 PoC

Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control.

CVE-2019-5137
Moxa General
7.5
HIGH
EPSS
0.5%
2019 CWE-321 1 PoC

The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

CVE-2019-5037
Nest Labs General
7.5
HIGH
EPSS
0.1%
2019 CWE-190 1 PoC

An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can send a specially crafted packet to trigger.

CVE-2019-10174
infinispan General
7.5
HIGH
EPSS
0.9%
2019 CWE-470 1 PoC

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.

CVE-2022-23990
Software Genérico General
7.5
HIGH
EPSS
3.7%
2022 3 PoCs

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.